Spam Fighting in Exchange
By Simon Bisson & Mary Branscombe in Editorial
How can you fight spam with one of the most common email servers out there? After all, surely that should mean it’s an easy play for the spammers, with enough holes to get every V1agr4 advert and pump-and-dump scam into your users’ mailboxes.
It turns out it isn’t - and that the built-in tools are effective spam blockers.
If you’re not using Exchange 2007 Content Filter (or Exchange 2007’s Intelligent Message Filter) turn them on. This is one of the most effective weapons in your arsenal. It’s regularly updated, and it scans messages for common spam formats. Mesages are categorised and given spam ratings, which you can use to reject, quarantine, or file messages in users’ Junk Mail folders. CF is surprisingly easy to use - set it up, set the basic filtering rules, and then occasionaly check your quarantine mail box for false positives.
Exchange 2007 has even added whitelisting for persistently filtered false positives. Once a domain is whitelisted, there’s no more delving in the spam folders for Twitter invites or press releases from Kaspersky and Sophos.
I’d been running my server like that for some time, when I discovered another trick that turned out to make a huge difference. Exchange actually supports using real-time block lists (RBLs), which are lists of spam IP addresses hosted by services like SpamCop and Spamhaus. It’s trivially easy to add new block lists to Exchange - just find the lookup address on the block list site (Spamhaus’ is zen.spamhaus.org), and add it and the provider name in the Block List Provider section of Exchange’s anti-spam tools.
Without RBL support turned on I was getting 500 or so spam messages in my quarantine a day, making it hard to filter out the few false positives. With it on, I’m down to less than 100. Managing my spam is a lot easier - and with whitelisting, I’m having to look in the spam folder a lot less often…
–Simon
Comment by Serge Fernell - August 6, 2008 on 9:53 am
NOTE CORRECTION: Spamhaus RBL (by far the most reliable and most effective of all) is: zen.spamhaus.org (the one mentioned in the article, sbl.spamhaus.org, is just one part of ZEN, you need to be using tive of all) is: zen.spamhaus.org if you want proper spam filtering)
Comment by Simon Bisson & Mary Branscombe - August 6, 2008 on 10:10 am
Thanks for that! I’ll amend the post accordingly…
…and update my mail server!
Comment by Jason - August 8, 2008 on 11:47 am
Interesting point about the Exchange 2007 Content Filter, we are currently running Mailsweeper and I wonder if the functionality of the built-in Exchange Filter is comparable?
RBL can be very useful for keeping a large majority of unwanted mail out but before implementing something like this a business has to be fully aware of the implications - especially from the risk of false negatives. I.e. genuine mail that fails to get through.
From time to time a valid sender can appear on a RBL through little fault of their own and the RBL filter will simply reject them - whilst many of these are probably unwanted anyway there is always the possibility of a customer order being lost. If that customer is an important customer they are unlikely to take kindly to an outright rejection of mail. We discovered this lesson the hard way. In the times we have experienced this with trading partners the sender has been unaware at the point of sending an email that they are on a blacklist.
Make a comment
Tag cloud
Archives
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
Most commented posts
- Java’s SSVAGENT.EXE: training the monkey
5 comments
- Wubi Tuesday
- Not very open, not very social
- The best mobile game ever
- A Big Day In The Enterprise IT World
- Employees are our most valuable asset (snigger)
- Biometrics - it's not the technology that's broken
- More battery life, fewer explosions
- Spam Fighting in Exchange
- IDF: Will SSD mean the end of 5GB free?
Highest Rated Blog Posts
- Nobody knows what Web 2.0 really is (100%)
- Songs of distant satellites (100%)
- Log in and lock in (100%)
- Mommy, why is there a home server in the office? (100%)
- Employees are our most valuable asset (snigger) (100%)
- Locking down IT or blocking creativity (100%)
- Video opera? What would you do with huge bandwidth and millions of pixels? (100%)
- Consumer BlackBerrys are good for business (100%)
- HD Trek (100%)
- Top tips for speeding up Vista (100%)

